CVE-2023-46223
- EPSS 3.25%
- Veröffentlicht 19.12.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:28:06
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
CVE-2023-41727
- EPSS 1.89%
- Veröffentlicht 19.12.2023 16:15:08
- Zuletzt bearbeitet 06.05.2025 19:15:58
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
CVE-2021-22962
- EPSS 27.82%
- Veröffentlicht 19.12.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:01
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
CVE-2023-41725
- EPSS 0.18%
- Veröffentlicht 03.11.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:21:33
Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability
CVE-2023-41726
- EPSS 0.06%
- Veröffentlicht 03.11.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:21:33
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
CVE-2022-43554
- EPSS 0.09%
- Veröffentlicht 03.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:26:46
Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
CVE-2022-43555
- EPSS 0.12%
- Veröffentlicht 03.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:26:46
Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
CVE-2023-32560
- EPSS 91.91%
- Veröffentlicht 10.08.2023 20:15:10
- Zuletzt bearbeitet 06.03.2025 16:15:41
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.
CVE-2023-32561
- EPSS 0.1%
- Veröffentlicht 10.08.2023 20:15:10
- Zuletzt bearbeitet 06.03.2025 16:15:41
A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.
CVE-2023-32562
- EPSS 27.34%
- Veröffentlicht 10.08.2023 20:15:10
- Zuletzt bearbeitet 06.03.2025 16:15:41
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.